Junglewise Threat Intelligence

CVE-2026-66434: Sayontan Sinha Photonic Gallery & Lightbox XSS in WordPress

CVE-2026-66434 · Severity: medium · CVSS 6.5 · Published 2026-07-27

Executive brief

Photonic Gallery & Lightbox is a WordPress plugin used to display photos from external services like Flickr and SmugMug. A security vulnerability allows users with 'Contributor' level access to inject malicious scripts into the website. If a site administrator or visitor views the affected content, these scripts could redirect users to malicious sites, display unauthorized advertisements, or compromise the viewer's session.

Technical details

The Photonic Gallery & Lightbox plugin for WordPress (versions 3.33 and below) is vulnerable to Stored Cross-Site Scripting (XSS) due to improper input sanitization and output escaping. An attacker with Contributor-level privileges can inject arbitrary JavaScript payloads into gallery settings or content. The vulnerability requires a victim (such as an administrator) to interact with the affected page for the script to execute in their browser context. This can lead to session hijacking or unauthorized actions performed on behalf of the victim. The issue is addressed in version 3.34.

Affected products

  • Sayontan Sinha Photonic Gallery & Lightbox for Flickr, SmugMug & Others <= 3.33

Timeline

  • 2026-07-13: disclosed: Reported by Ananda Dhakal via Patchstack
  • 2026-07-27: advisory: NVD and Patchstack published advisory details
  • 2026-07-27: patched: Version 3.34 released to address the vulnerability

References